Earlier quoted context omitted.
I'm not a lawyer either, but have been going through the GDPR process at my job. It doesn't matter if you operate or are established in the EU. If you have EU visitors/users they gain the protections of the GDPR and you have to comply. GDPR affects any org/site that collects personal or sensitive data. Amongst many others IP address and email address are considered PII under GDPR. We use IP address for some high leve…
I'm very interested to see how such requests would actually work...mainly because I'm curious to see what actual authority the EU has to enforce its laws outside of its borders. I understand it applying to companies that are doing business in Europe but beyond that...?
It might suck if the EU started blocking payments to you.